U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2021-20487

Change History

Initial Analysis by NIST 6/02/2021 4:36:18 PM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:ibm:power9_system_firmware:*:*:*:*:*:*:*:* versions from (including) fw940.00 up to (excluding) fw940.20
          *cpe:2.3:o:ibm:power9_system_firmware_firmware:*:*:*:*:*:*:*:* versions from (including) fw930.00 up to (excluding) fw930.30
     OR
          cpe:2.3:h:ibm:9008-22l:-:*:*:*:*:*:*:*
          cpe:2.3:h:ibm:9009-22a:-:*:*:*:*:*:*:*
          cpe:2.3:h:ibm:9009-41a:-:*:*:*:*:*:*:*
          cpe:2.3:h:ibm:9009-42a:-:*:*:*:*:*:*:*
          cpe:2.3:h:ibm:9040-mr9:-:*:*:*:*:*:*:*
          cpe:2.3:h:ibm:9080-m9s:-:*:*:*:*:*:*:*
          cpe:2.3:h:ibm:9223-22h:-:*:*:*:*:*:*:*
          cpe:2.3:h:ibm:9223-42h:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:ibm:power9_system_firmware:*:*:*:*:*:*:*:* versions up to (excluding) fw950.00
     OR
          cpe:2.3:h:ibm:9009-22g:-:*:*:*:*:*:*:*
          cpe:2.3:h:ibm:9009-41g:-:*:*:*:*:*:*:*
          cpe:2.3:h:ibm:9009-42g:-:*:*:*:*:*:*:*
          cpe:2.3:h:ibm:9223-22s:-:*:*:*:*:*:*:*
          cpe:2.3:h:ibm:9223-42s:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:ibm:scale-out_lc_system_firmware:*:*:*:*:*:*:*:* versions up to (excluding) op940.20
     OR
          cpe:2.3:h:ibm:8335-gth:-:*:*:*:*:*:*:*
          cpe:2.3:h:ibm:8335-gtx:-:*:*:*:*:*:*:*
          cpe:2.3:h:ibm:9183-22x:-:*:*:*:*:*:*:*
Added CVSS V2

								
							
							
						
NIST (AV:N/AC:L/Au:S/C:P/I:P/A:P)
Added CVSS V3.1

								
							
							
						
NIST AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Added CWE

								
							
							
						
NIST CWE-347
Changed Reference Type
https://exchange.xforce.ibmcloud.com/vulnerabilities/197730 No Types Assigned
https://exchange.xforce.ibmcloud.com/vulnerabilities/197730 VDB Entry, Vendor Advisory
Changed Reference Type
https://www.ibm.com/support/pages/node/6455911 No Types Assigned
https://www.ibm.com/support/pages/node/6455911 Vendor Advisory